All Apps and Add-ons

Microsoft Azure Add-on for Splunk: Why isn't data coming in using event hub input only (is account info required for configuration)?

tvanry
Engager

If we are only adding an event hub input using the Microsoft Azure Add-on for Splunk, do we need to include account information on the configuration tab?

We haven't put in any account information on the configuration tab and are only using an event hub input, but we aren't seeing any data coming in.

0 Karma
1 Solution

jconger
Splunk Employee
Splunk Employee

You do not need the account information for the Event Hub input. The account information is necessary for the other inputs as they use REST APIs, and the account is used to authenticate to those APIs. The Event Hub input only needs the connection string (no account).

View solution in original post

jconger
Splunk Employee
Splunk Employee

You do not need the account information for the Event Hub input. The account information is necessary for the other inputs as they use REST APIs, and the account is used to authenticate to those APIs. The Event Hub input only needs the connection string (no account).

tvanry
Engager

Any other places to check as to why we are not seeing data come in to Splunk?

0 Karma

jconger
Splunk Employee
Splunk Employee

Here are the 3 most common issues:

  • Using a Splunk 8 instance - the Event Hub input does not work on Splunk 8 (yet)
  • Entering an Event Hub key instead of an Event Hub connection string

alt text

  • Entering an Event Hub Namespace instead of an individual Event Hub Name

alt text

0 Karma

tvanry
Engager

Thanks Jason. It appears that our problem might be firewall related.

0 Karma

tvanry
Engager

Confirmed that this all works after the firewall was opened up. We had to open our heavy forwarder to be able to reach port 5671.

0 Karma

rluhar_fs
Explorer

What is your splunk version? I am having issue but my splunk is also in Azure and I am on 8.0.3 version.

0 Karma

tvanry
Engager

Our Splunk version is 7.2.7. The event hub collector is not compatible with Splunk 8. See @jconger response above.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...